Research
HTTP/2 Server Push and Multiplexing Are an Untapped Website-Fingerprinting Defense
arXiv 2609.05119 moves website fingerprinting defense from the encapsulating protocol layer, Tor and VPN, down to the application layer, showing that known defenses HTTPOS, LLaMA, FRONT and Tamaraw can be emulated client-side through HTTP/2 features and ALPaCA and Tamaraw server-side. It argues proactive resource suggestion, multiplexing and flow control offer lightweight defenses deployable at both endpoints. Evaluation uses a unified blueprint that calibrates defense parameters per dataset, then combines hyperparameter-tuned attack models, two information-theoretic leakage estimators for residual uncertainty, and overhead measurements.
↳ Follow the thread